Firewall Log - ZyXEL Communications ZYWALL2 ET 2WE User Manual

Internet security gateway
Table of Contents

Advertisement

ZyWALL 2 Series User's Guide
Filter log Message Format
SdcmdSyslogSend(SYSLOG_FILLOG, SYSLOG_NOTICE, String );
String = IP[Src=xx.xx.xx.xx Dst=xx.xx.xx.xx prot spo=xxxx dpo=xxxx] S04>R01mD
IP[...] is the packet header and S04>R01mD means filter set 4 (S) and rule 1 (R), match (m) drop
(D).
Src: Source Address
Dst: Destination Address
prot: Protocol ("TCP","UDP","ICMP")
spo: Source port
dpo: Destination port
Mar 03 10:39:43 202.132.155.97 Nortel:
GEN[fffffffffffnordff0080] }S05>R01mF
Mar 03 10:41:29 202.132.155.97 Nortel:
GEN[00a0c5f502fnord010080] }S05>R01mF
Mar 03 10:41:34 202.132.155.97 Nortel:
IP[Src=192.168.2.33 Dst=202.132.155.93 ICMP]}S04>R01mF
Mar 03 11:59:20 202.132.155.97 Nortel:
GEN[00a0c5f502fnord010080] }S05>R01mF
Mar 03 12:00:52 202.132.155.97 Nortel:
GEN[ffffffffffff0080] }S05>R01mF
Mar 03 12:00:57 202.132.155.97 Nortel:
GEN[00a0c5f502010080] }S05>R01mF
Mar 03 12:01:06 202.132.155.97 Nortel:
IP[Src=192.168.2.33 Dst=202.132.155.93 TCP spo=01170
4. PPP log
PPP Log Message Format
SdcmdSyslogSend( SYSLOG_PPPLOG, SYSLOG_NOTICE, String );
String = ppp:Proto Starting / ppp:Proto Opening / ppp:Proto Closing / ppp:Proto Shutdown
Proto = LCP / ATCP / BACP / BCP / CBCP / CCP / CHAP/ PAP / IPCP /
IPXCP
Jul 19 11:42:44 192.168.202.2 Nortel: ppp:LCP Closing
Jul 19 11:42:49 192.168.202.2 Nortel: ppp:IPCP Closing
Jul 19 11:42:54 192.168.202.2 Nortel: ppp:CCP Closing

5. Firewall log

Firewall Log Message Format
SdcmdSyslogSend(SYSLOG_FIREWALL, SYSLOG_NOTICE, buf);
buf = IP[Src=xx.xx.xx.xx : spo=xxxx Dst=xx.xx.xx.xx : dpo=xxxx | prot | rule | action]
Src: Source Address
spo: Source port (empty means no source port information)
Dst: Destination Address
dpo: Destination port (empty means no destination port information)
prot: Protocol ("TCP","UDP","ICMP", "IGMP", "GRE", "ESP")
rule: <a,b> where a means "set" number; b means "rule" number.
Action: nothing(N) block (B) forward (F)
08-01-2000
11:48:41 Local1.Notice
>172.21.1.80
:137
08-01-2000
11:48:41 Local1.Notice
>192.168.77.88
:520
08-01-2000
11:48:39 Local1.Notice
|IGMP<2>|default permit:<2,0>|B
08-01-2000
11:48:39 Local1.Notice
|IGMP<2>|default permit:<2,0>|B
32-8
192.168.20.10
|UDP|default permit:<2,0>|B
192.168.20.10
|UDP|default permit:<2,0>|B
192.168.20.10
192.168.20.10
dpo=00021]}S04>R01mF
RAS: FW 172.21.1.80
RAS: FW 192.168.77.88
RAS: FW 172.21.1.50
RAS: FW 172.21.1.25
System Information and Diagnosis
:137
-
:520
-
->172.21.1.50
->172.21.1.25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 2Zywall 2we

Table of Contents